All guided builds

Guided buildcore8 steps~20 min5 devices

NAT to the internet

Hide two private office LANs behind the single public address your provider gave you.

What you'll be able to do: Two private LANs share one public address on the internet: every packet leaves the office as 203.0.113.2, the provider's anti-spoofing filter lets it through, and the translation table shows exactly which inside host each one belongs to.

Topics: NAT · PAT overload · RFC 1918 · Default route · Public vs private addressing

What you'll build

Step by step

  1. 1. Place the edge router and address the first LAN

    Every office reaches the internet through one router with a foot in both worlds. Drag a router on, name it Edge, and give Gi0/0 the address 192.168.10.1. That range comes out of RFC 1918, the block reserved for private use — which is precisely why it is going to need translating before it can leave the building.

    On Edge — Name the router and address the first inside LAN

    enable
    configure terminal
    hostname Edge
    interface Gi0/0
    ip address 192.168.10.1 255.255.255.0
    no shutdown
    exit
    end

    Check: run show ip interface brief on Edge and look for Gi0/0 192.168.10.1 YES manual down down.

    Why: RFC 1918 sets aside three ranges — 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 — that any organisation may use internally without asking anyone. The price of that freedom is that they are not unique: thousands of networks use the same addresses, so the public internet does not carry them at all.

  2. 2. Put a workstation on the first LAN

    Cable a PC into Gi0/0 and give it an address from the same /24 with the router as its default gateway. A host holding a private address is not crippled — inside the office it is complete and fully usable. The address only becomes a problem at the moment it tries to leave.

    • Cable PC-A Eth0 ↔ Edge Gi0/0

    On PC-A — Name the workstation and set address, mask and gateway in one line

    hostname PC-A
    ipconfig Eth0 192.168.10.10 255.255.255.0 192.168.10.1

    Check: run route print on PC-A and look for 0.0.0.0 0.0.0.0 192.168.10.1 Eth0.

    Why: NAT is invisible to the host: PC-A keeps using its private address as the source of every packet it sends and never learns that the address is rewritten at the edge. Nothing on the PC changes when NAT is added later, which is what makes it possible to add translation to a network that is already running.

  3. 3. Add a second private LAN on the other port

    Offices are rarely one subnet, and the word "overload" only means something once several hosts are competing for one public address. Give Gi0/1 a second private range and hang PC-B off it. The two LANs can already talk to each other — routing between directly connected networks is the router's ordinary day job and needs no extra configuration.

    • Cable PC-B Eth0 ↔ Edge Gi0/1

    On Edge — Address the second inside LAN

    enable
    configure terminal
    interface Gi0/1
    ip address 192.168.20.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-B — Name the second workstation and address it in the second LAN

    hostname PC-B
    ipconfig Eth0 192.168.20.10 255.255.255.0 192.168.20.1

    Check: run show ip route on Edge and look for C 192.168.20.0/24 is directly connected, Gi0/1.

    Why: Translation happens only where traffic crosses from an inside interface to an outside one, never between two inside networks. PC-A and PC-B talk with their real addresses because both subnets are connected to Edge, and the translation added later will touch only traffic leaving through the WAN port.

  4. 4. Rent a link to the provider

    Drag in a second router to play the provider and join the two with a serial WAN cable. The /30 between them carries exactly two usable addresses, and 203.0.113.2 on Edge is the only public address this office owns — one address, for every host behind it. Remember that number; the rest of the build is about making it stretch.

    • Cable Edge Se0/0/0 ↔ ISP Se0/0/0 (serial)

    On ISP — Name the provider router and address its end of the WAN link

    enable
    configure terminal
    hostname ISP
    interface Se0/0/0
    ip address 203.0.113.1 255.255.255.252
    no shutdown
    exit
    end

    On Edge — Address the office end of the WAN link

    enable
    configure terminal
    interface Se0/0/0
    ip address 203.0.113.2 255.255.255.252
    no shutdown
    exit
    end

    Check: run show ip interface brief on Edge and look for Se0/0/0 203.0.113.2 YES manual up up.

    Why: Public IPv4 addresses are scarce — the free pool ran out years ago — so a small customer is usually given a handful, often exactly one, on a link sized to fit. 203.0.113.0/24 itself is one of the ranges reserved for documentation, which is why labs and textbooks use it instead of someone's real address.

  5. 5. Put a public server on the far side

    Give the provider a second network with a web server on it. 198.51.100.50 is a public address in every sense that matters: globally unique, routable, and belonging to one machine anywhere on earth — the opposite of the two LANs behind Edge.

    • Cable WEB1 Eth0 ↔ ISP Gi0/0

    On ISP — Address the provider's public LAN

    enable
    configure terminal
    interface Gi0/0
    ip address 198.51.100.1 255.255.255.0
    no shutdown
    exit
    end

    On WEB1 — Name the server and give it a public address and gateway

    hostname WEB1
    ipconfig Eth0 198.51.100.50 255.255.255.0 198.51.100.1

    Check: run show ip route on ISP and look for C 198.51.100.0/24 is directly connected, Gi0/0.

    Why: Uniqueness is what makes an address routable across networks you do not control: every provider on the path can hold one route toward 198.51.100.0/24 and know it leads to exactly one place. A private range can never offer that, because the same prefix is in use behind thousands of different routers at once.

  6. 6. Point the office at the provider

    Edge knows its own three connected networks and nothing else in the world. One default route hands every unknown destination to the provider. Ping 198.51.100.50 from PC-A now and it answers — hold that result lightly, because the packet just crossed the provider carrying a source address of 192.168.10.10.

    On Edge — Send everything Edge does not recognise out of the WAN link

    enable
    configure terminal
    ip route 0.0.0.0 0.0.0.0 203.0.113.1
    end

    On PC-A — Try the public server for the first time

    ping 198.51.100.50

    Check: run show ip route on Edge and look for S* 0.0.0.0/0 via 203.0.113.1, Se0/0/0.

    Why: Longest-prefix match decides which route wins: a /24 beats a /16, and anything beats the /0 of a default route, which matches every destination with zero bits in common. Adding a default therefore changes nothing for Edge's connected LANs; it only gives a destination to traffic that would otherwise have been dropped.

  7. 7. The provider filters private sources, and the ping dies

    192.168.10.10 is not one address — it is millions of them, live in every office on earth at the same moment, so no provider will carry it and no reply could ever find its way home. Install the RFC 1918 anti-spoofing filter that every real carrier runs on its customer-facing port, and watch both workstations go dark one hop after they leave the building.

    On ISP — Refuse any packet arriving from the office with a private source address

    enable
    configure terminal
    ip access-list extended NO-PRIVATE
    deny ip 192.168.0.0 0.0.255.255 any
    deny ip 10.0.0.0 0.255.255.255 any
    deny ip 172.16.0.0 0.15.255.255 any
    permit ip any any
    exit
    interface Se0/0/0
    ip access-group NO-PRIVATE in
    end

    On PC-A — Try the same ping again, now that the provider is filtering

    ping 198.51.100.50

    Check: run show access-lists on ISP and look for 10 deny ip 192.168.0.0 0.0.255.255 any.

    Why: A packet's source address is only a claim, and a private one cannot be traced to any one customer, so providers drop packets whose source could not legitimately come from the customer's link — the practice known as ingress filtering, described in BCP 38. It stops spoofed and unroutable traffic at the edge, before it can enter the provider's network.

  8. 8. Translate the whole office onto one public address

    NAT overload — PAT — rewrites the source of every outbound packet to the router's own public address, and remembers which inside host it belonged to by handing each conversation its own port number. Mark the two LAN ports `inside`, mark the WAN port `outside`, list the private ranges allowed to translate, then commit the rule. Read `show ip nat translations` afterwards: 192.168.10.10 and 192.168.20.10 both leave as 203.0.113.2, told apart only by port — that is the whole trick behind the word "overload".

    On Edge — Declare which side is inside and which is outside

    enable
    configure terminal
    interface Gi0/0
    ip nat inside
    exit
    interface Gi0/1
    ip nat inside
    exit
    interface Se0/0/0
    ip nat outside
    exit
    end

    On Edge — Select the private ranges, then translate them onto the WAN address

    enable
    configure terminal
    access-list 1 permit 192.168.10.0 0.0.0.255
    access-list 1 permit 192.168.20.0 0.0.0.255
    ip nat inside source list 1 interface Se0/0/0 overload
    end

    On PC-A — The same ping, now with a public source address

    ping 198.51.100.50

    On PC-B — And from the second LAN, sharing that one address

    ping 198.51.100.50

    Check: run show ip nat translations on Edge and look for icmp 203.0.113.2:1024 192.168.10.10:1024 198.51.100.50.

    Why: Replies come back addressed to 203.0.113.2 and the port Edge assigned — a destination the provider can route — and Edge looks that port up in its translation table to rewrite the packet back to the right inside host. The access list only selects which sources are translated: traffic it does not match is not blocked, it simply leaves untranslated.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
NAT to the internet — step-by-step network lab · NetForge-AI